Back to skill

Security audit

Polymarket 24h Precipitation Range Trader

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Polymarket trading skill that defaults to simulated trading and only uses real funds when run with an explicit live flag.

Install only if you understand it is a trading bot. Test in paper mode first, protect and scope the `SIMMER_API_KEY`, review the installed `simmer-sdk` package, set conservative trade limits, and use `--live` only when you accept the risk of real USDC losses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest defines a managed trading automaton with an entrypoint but provides no explicit trigger gating, schedule, or activation constraints. In a trading context, ambiguous activation semantics can cause the bot to run whenever the platform permits, increasing the risk of unintended order placement, excessive trading, or operation under conditions the user did not explicitly authorize.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal